Data processing and scanning systems for assessing vendor risk
Abstract
Data processing systems and methods, according to various embodiments, are adapted for automatically assessing the level of security and/or privacy risk associated with doing business with a particular vendor or other entity. In various embodiments, the systems may automatically obtain and use any suitable information to assess such risk levels including, for example: (1) any security and/or privacy certifications held by the vendor; (2) the terms of one or more contracts between a particular entity and the vendor; (3) the results of one or more privacy impact assessments for the vendor; and/or (4) any other suitable data. The system may be configured to automatically approve or reject a particular vendor based on the assessed risk level associated with the vendor and this information may be automatically communicated to an entity considering doing business with the vendor and/or the vendor itself
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented data processing method for assessing a level of privacy-related risk associated with a particular vendor, the method comprising:
receiving, by one or more processors, a request for an assessment of privacy-related risk associated with the particular vendor; in response to receiving the request, retrieving, by one or more processors, from a vendor information database, current vendor information associated with the particular vendor, wherein the current vendor information associated with the particular vendor comprises both vendor privacy risk assessment information associated with the particular vendor and a vendor privacy risk score for the particular vendor; determining, by one or more processors, based at least in part on the vendor privacy risk assessment information, to request updated vendor privacy risk assessment information for the particular vendor; in response to determining to request the updated vendor privacy risk assessment information:
generating, by one or more processors, a vendor privacy risk assessment questionnaire,
transmitting, by one or more processors, the vendor privacy risk assessment questionnaire to the particular vendor,
receiving, by one or more processors, one or more vendor privacy risk assessment questionnaire responses from the particular vendor, and
storing, by one or more processors in the vendor information database, the vendor privacy risk assessment questionnaire responses as the updated vendor privacy risk assessment information;
calculating, by one or more processors based at least in part on the updated vendor privacy risk assessment information, an updated privacy risk score for the particular vendor; storing, by one or more processors in the vendor information database, the updated privacy risk score for the particular vendor; and communicating, by one or more processors, the updated privacy risk score for the particular vendor to one or more users.
2 . The computer-implemented data processing method of claim 1 , where communicating the updated privacy risk score comprises displaying the updated privacy risk score to the one or more users on a computer display.
3 . The computer-implemented data processing method of claim 1 , wherein determining to request the updated vendor privacy risk assessment information comprises determining that the vendor privacy risk assessment information associated with the particular vendor has expired.
4 . The computer-implemented data processing method of claim 1 , wherein determining to request the updated vendor privacy risk assessment information comprises determining that the vendor privacy risk score for the particular vendor has expired.
5 . The computer-implemented data processing method of claim 1 , further comprising:
determining, by one or more computer processors, based at least in part on the updated privacy risk score for the particular vendor, to approve the particular vendor as being suitable for doing business with a particular entity; and in response to determining to approve the particular vendor, storing, by one or more computer processors, an indication of approval of the particular vendor.
6 . The computer-implemented data processing method of claim 1 , further comprising:
determining, by one or more processors, based at least in part on the updated privacy risk score for the particular vendor, to automatically reject the particular vendor as a candidate for doing business with a particular entity; and responsive to determining to reject the particular vendor, storing, by one or more computer processors, an indication of rejection of the particular vendor.
7 . The computer-implemented data processing method of claim 1 , wherein the current vendor information associated with the particular vendor further comprises one or more documents related to the particular vendor's privacy practices,
wherein the method further comprises analyzing the one or more documents using one or more natural language processing techniques to identify particular terms in the one or more documents, and wherein calculating the updated privacy risk score for the particular vendor is further based, at least in part, on one or more particular terms in the one or more documents.
8 . The computer-implemented data processing method of claim 7 , wherein the current vendor information associated with the particular vendor further comprises publicly available privacy-related information associated with the particular vendor, and
wherein calculating the updated privacy risk score for the particular vendor is further based, at least in part, on the publicly available privacy-related information associated with the particular vendor.
9 . A data processing system for assessing privacy risk associated with a particular vendor, the system comprising:
one or more processors; and computer memory storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
receiving a request for vendor privacy risk information for a particular vendor;
retrieving, from a vendor information database, current vendor information associated with the particular vendor and a vendor privacy risk rating for the particular vendor;
automatically determining, based at least in part on the current vendor information associated with the particular vendor, to obtain updated vendor information associated with the particular vendor;
in response to determining to obtain the updated vendor information associated with the particular vendor, requesting the updated vendor information associated with the particular vendor;
receiving the updated vendor information associated with the particular vendor;
storing the updated vendor information associated with the particular vendor in the vendor information database;
calculating an updated vendor privacy risk rating for the particular vendor based at least in part on the updated vendor information associated with the particular vendor;
storing the updated vendor privacy risk rating for the particular vendor in the vendor information database; and
communicating the updated vendor privacy risk rating for the particular vendor to at least one user.
10 . The data processing system of claim 9 , wherein retrieving, from the vendor information database, the current vendor information associated with the particular vendor comprises:
accessing, from the vendor information database, a privacy-related data map that identifies one or more electronic associations between at least two data assets within a data model, the data model comprising a respective digital inventory for each of the at least two data assets, each respective digital inventory comprising one or more respective inventory attributes selected from a group consisting of:
one or more processing activities associated with each of the respective data assets,
transfer data associated with each of the respective data assets, and
respective identifiers of one or more pieces of personal data associated with each of the respective data assets; and
determining at least a subset of the current vendor information associated with the particular vendor based on one or more digital inventories of the data model.
11 . The data processing system of claim 9 , wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor comprises:
determining, based at least in part on the current vendor information associated with the particular vendor, that no vendor privacy risk assessment information associated with the particular vendor is stored in the vendor information database.
12 . The data processing system of claim 9 , wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor is done at least partially in response to determining, based at least in part on the current vendor information associated with the particular vendor, that the particular vendor has experienced a particular type of privacy-related incident.
13 . The data processing system of claim 9 , wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor is executed at least partially in response to determining, based at least in part on the current vendor information associated with the particular vendor, that the particular vendor is associated with a new sub-processor.
14 . The data processing system of claim 9 , wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor is executed at least partially in response to determining, based at least in part on the current vendor information associated with the particular vendor, that a security certification for the particular vendor has expired.
15 . The data processing system of claim 9 , wherein the current vendor information associated with the particular vendor comprises a plurality of pieces of information associated with the particular vendor; and
wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor comprises:
determining an expiration date for at least one of the plurality of pieces of information associated with the particular vendor, and
determining that the at least one of the plurality of pieces of information associated with the particular vendor has expired.
16 . The data processing system of claim 9 , wherein determining, based at least in part on the current vendor information associated with the particular vendor, to obtain the updated vendor information associated with the particular vendor is executed at least partially in response to determining, based at least in part on the current vendor information associated with the particular vendor, that a vendor privacy risk assessment for the particular vendor has expired; and
wherein requesting the updated vendor information associated with the particular vendor comprises:
generating a vendor privacy risk assessment questionnaire, and
transmitting the vendor privacy risk assessment questionnaire to the particular vendor for completion.
17 . A computer-implemented data processing method for assessing a risk associated with a vendor, the method comprising:
receiving, by one or more computer processors, an indication that an entity wishes to do business with, or submit payment to, a particular vendor; at least partially in response to receiving the indication, obtaining, by one or more computer processors, information from a centralized vendor risk information database regarding whether a new risk assessment is needed for the vendor; at least partially in response to determining that a new risk assessment is needed for the vendor, automatically facilitating, by one or more computer processors, the completion of a new or updated risk assessment for the vendor; saving, by one or more computer processors, the new or updated risk assessment to system memory; and communicating, by one or more computer processors, information from the new risk assessment to the entity for use in determining whether to contract with, or submit payment to, the particular vendor.
18 . The computer-implemented data processing method of claim 17 , wherein the indication is an indication that the entity wishes to establish a new business relationship with the particular vendor.
19 . The computer-implemented data processing method of claim 17 , wherein the indication is an indication that the entity wishes to renew an existing business relationship with the particular vendor.
20 . The computer-implemented data processing method of claim 17 , wherein the indication is an indication that the entity wishes to submit payment to particular vendor.
21 . The computer-implemented data processing method of claim 17 , wherein the information regarding whether a new risk assessment is needed for the vendor indicates that an updated risk assessment is needed for the vendor.
22 . The computer-implemented data processing method of claim 17 , wherein the information regarding whether a new risk assessment is needed for the vendor comprises information indicating that the vendor has been involved in a privacy-related incident.
23 . The computer-implemented data processing method of claim 17 , wherein the information regarding whether a new risk assessment is needed for the vendor comprises information indicating that an existing privacy assessment for the vendor is outdated.
24 . The computer-implemented data processing method of claim 17 , wherein the existing privacy assessment is stored in the centralized vendor risk information database.
25 . A computer-implemented data processing method for assessing privacy risk associated with a particular vendor, the method comprising:
receiving, by one or more processors, a request for vendor privacy risk information for a particular vendor; at least partially in response to receiving the request, retrieving, by one or more processors from a vendor information database, current vendor information associated with the particular vendor and a vendor privacy risk rating for the particular vendor; determining, by one or more processors based at least in part on the current vendor information associated with the particular vendor, to request updated vendor information associated with the particular vendor; at least partially in response to determining to request the updated vendor information associated with the particular vendor, requesting, by one or more processors, the updated vendor information associated with the particular vendor; receiving, by one or more processors, the updated vendor information associated with the particular vendor; storing, by one or more processors in the vendor information database, the updated vendor information associated with the particular vendor; calculating, by one or more processors, based at least in part on the updated vendor information associated with the particular vendor, an updated privacy risk rating for the particular vendor; storing, by one or more processors in the vendor information database, the updated privacy risk rating for the particular vendor; and communicating the updated privacy risk rating for the particular vendor to at least one user.
26 . The computer-implemented data processing method of claim 25 , wherein the communicating step further comprises communicating a subset of the updated vendor information associated with the particular vendor to the at least one user.
27 . The computer-implemented data processing method of claim 26 , wherein receiving the request for the vendor privacy risk information for the particular vendor comprises detecting a selection on a graphical user interface.
28 . The computer-implemented data processing method of claim 26 , further comprising:
obtaining, using at least a portion of the updated vendor information associated with the particular vendor, publicly available privacy-related information associated with the particular vendor, wherein calculating the updated privacy risk rating for the particular vendor is based at least in part on the publicly available privacy-related information associated with the particular vendor.
29 . The computer-implemented data processing method of claim 26 , wherein the updated vendor information associated with the particular vendor comprises one or more pieces of information associated with the particular vendor selected from a group consisting of:
(1) one or more services provided by the particular vendor; (2) a name of the particular vendor; (3) a geographical location of the particular vendor; (4) a description of the particular vendor; and (5) one or more employees of the particular vendor.
30 . The computer-implemented data processing method of claim 26 , wherein the current vendor information associated with the particular vendor comprises one or more documents; and
wherein determining, based at least in part on the current vendor information associated with the particular vendor, to request the updated vendor information associated with the particular vendor comprises:
determining an expiration date associated with at least one of the one or more documents, and
determining that the at least one of the one or more documents has expired.Join the waitlist — get patent alerts
Track US2020004938A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.